CVE-2017-12874: Input Validation
Published Dec 3, 2016
·Updated
Incorrect signature verification
Other sources
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
Affected Software
7 affected componentsFixes available
composer/simplesamlphp/simplesamlphp-module-infocard<1.0.1
debian/simplesamlphp
1.16.3-1+deb10u21.16.3-1+deb10u11.19.0-11.19.7-1
composer/simplesamlphp/simplesamlphp-module-infocard<1.0.1
1.0.1
SimpleSAMLphp Infocard Module Simplesamlphp=1.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Dec 3, 2016
Advisory Published
12:16 PM
Sep 1, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12874?
CVE-2017-12874 has a moderate severity level due to its impact on the integrity of XML message signatures.
2
How do I fix CVE-2017-12874?
To mitigate CVE-2017-12874, upgrade to SimpleSAMLphp module InfoCard version 1.0.1 or later.
3
Which versions of SimpleSAMLphp are affected by CVE-2017-12874?
CVE-2017-12874 affects versions of SimpleSAMLphp module InfoCard prior to 1.0.1.
4
What type of vulnerability is CVE-2017-12874?
CVE-2017-12874 is a vulnerability related to incorrect signature verification.
5
Can CVE-2017-12874 lead to XML message spoofing?
Yes, CVE-2017-12874 allows attackers to spoof XML messages by exploiting the vulnerability in signature validation.